Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 URGENT NEWS TO ALL BNET ACC USERS, our accs are compromised

views
     
TSThe Amateur Working Bee
post Aug 10 2012, 08:36 AM, updated 14y ago

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
change your passwords and security questions now, ill post the link of the security breach in blizz server once i bypass my office firewall to get the link

apparently your authenticator data is also compromised

This post has been edited by The Amateur Working Bee: Aug 10 2012, 08:39 AM
memphiz_zero88
post Aug 10 2012, 08:44 AM

My stars has gone. T_T
Group Icon
Staff
2,255 posts

Joined: Jul 2008
From: meditating at Mt Emei
http://us.blizzard.com/en-us/securityupdate.html
QUOTE

Players and Friends,

Even when you are in the business of fun, not every week ends up being fun. This week, our security team found an unauthorized and illegal access into our internal network here at Blizzard. We quickly took steps to close off this access and began working with law enforcement and security experts to investigate what happened.

At this time, we’ve found no evidence that financial information such as credit cards, billing addresses, or real names were compromised. Our investigation is ongoing, but so far nothing suggests that these pieces of information have been accessed.

Some data was illegally accessed, including a list of email addresses for global Battle.net users, outside of China. For players on North American servers (which generally includes players from North America, Latin America, Australia, New Zealand, and Southeast Asia) the answer to the personal security question, and information relating to Mobile and Dial-In Authenticators were also accessed. Based on what we currently know, this information alone is NOT enough for anyone to gain access to Battle.net accounts.

We also know that cryptographically scrambled versions of Battle.net passwords (not actual passwords) for players on North American servers were taken. We use Secure Remote Password protocol (SRP) to protect these passwords, which is designed to make it extremely difficult to extract the actual password, and also means that each password would have to be deciphered individually. As a precaution, however, we recommend that players on North American servers change their password. Please click this link to change your password. Moreover, if you have used the same or similar passwords for other purposes, you may want to consider changing those passwords as well.

In the coming days, we'll be prompting players on North American servers to change their secret questions and answers through an automated process. Additionally, we'll prompt mobile authenticator users to update their authenticator software. As a reminder, phishing emails will ask you for password or login information. Blizzard Entertainment emails will never ask for your password. We deeply regret the inconvenience to all of you and understand you may have questions. Please find additional information here.

We take the security of your personal information very seriously, and we are truly sorry that this has happened.

Sincerely,
Mike Morhaime
This post has been edited by memphiz_zero88: Aug 10 2012, 08:45 AM
xinan08
post Aug 10 2012, 08:44 AM

New Member
*
Junior Member
13 posts

Joined: Jan 2009
From: kepong



QUOTE(The Amateur Working Bee @ Aug 10 2012, 08:36 AM)
change your passwords and security questions now, ill post the link of the security breach in blizz server once i bypass my office firewall to get the link

apparently your authenticator data is also compromised
*
http://sea.blizzard.com/en-sg/securityupdate.html
TSThe Amateur Working Bee
post Aug 10 2012, 08:45 AM

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
QUOTE(CrazySpeakers @ Aug 10 2012, 08:43 AM)
or you could post your password here . we will assist you in the process.
*
or you can post yours here ill assist you too
xinan08
post Aug 10 2012, 08:45 AM

New Member
*
Junior Member
13 posts

Joined: Jan 2009
From: kepong



no wonder feel likes slowpokey..these 2 weeks!!
bxbo
post Aug 10 2012, 08:55 AM

New Member
*
Junior Member
9 posts

Joined: Jun 2012
ID : MashnalWashahnal
Pass : shesawaseashore

Someone please assist me, I've no idea what am I supposed to do right now. Thank you support team.
yuhhaur
post Aug 10 2012, 09:06 AM

I came. I saw. I help
*******
Senior Member
3,757 posts

Joined: Jan 2003
From: E A R T H
Username: username
Password: password

HELP ME!
TSThe Amateur Working Bee
post Aug 10 2012, 09:10 AM

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
some of you have rly bad taste in humour, typical malaysians lol
BotakPrince
post Aug 10 2012, 09:12 AM

Casual
***
Junior Member
388 posts

Joined: Oct 2005


will it affect our paypal accounts, info etc?
TSThe Amateur Working Bee
post Aug 10 2012, 09:15 AM

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
QUOTE(BotakPrince @ Aug 10 2012, 09:12 AM)
will it affect our paypal accounts, info etc?
*
from what "THEY" said its not affected, but lol...u believe them? if you dont want to take the risk, do the neccesary precautions lor
memphiz_zero88
post Aug 10 2012, 09:22 AM

My stars has gone. T_T
Group Icon
Staff
2,255 posts

Joined: Jul 2008
From: meditating at Mt Emei
QUOTE(BotakPrince @ Aug 10 2012, 09:12 AM)
will it affect our paypal accounts, info etc?
*
how's paypal account is affected? i thought blizz server yang kena hack.
TSThe Amateur Working Bee
post Aug 10 2012, 09:26 AM

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
QUOTE(memphiz_zero88 @ Aug 10 2012, 09:22 AM)
how's paypal account is affected? i thought blizz server yang kena hack.
*
something related to acc info iirc, they did state something like that, nvr used paypal, so idk what kinda risk paypal users are gonna face, but credit card user if kena hahahaa...rly gg

QUOTE
At this time, we’ve found no evidence that financial information such as credit cards, billing addresses, or real names were compromised. Our investigation is ongoing, but so far nothing suggests that these pieces of information have been accessed.

Quazacolt
post Aug 10 2012, 09:27 AM

Riding couple
*******
Senior Member
5,366 posts

Joined: Jan 2007
From: KL Malaysia


http://forum.lowyat.net/topic/2464271 gggg baby baby baby baby


TSThe Amateur Working Bee
post Aug 10 2012, 09:30 AM

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
well i think the worst part is how quick are they gonna prompt the security question change, since we cant change it manually without the admin allowing it
memphiz_zero88
post Aug 10 2012, 09:39 AM

My stars has gone. T_T
Group Icon
Staff
2,255 posts

Joined: Jul 2008
From: meditating at Mt Emei
sia-sia je buat password panjang berjela, have to change to another one vmad.gif
BotakPrince
post Aug 10 2012, 09:42 AM

Casual
***
Junior Member
388 posts

Joined: Oct 2005


just changed my password for paypal.

gonna change my d3 password next.

in that order of importance. hahahhha
TSThe Amateur Working Bee
post Aug 10 2012, 09:42 AM

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
QUOTE(memphiz_zero88 @ Aug 10 2012, 09:39 AM)
sia-sia je buat password panjang berjela, have to change to another one vmad.gif
*
exactly what im feeling now lol, lucky i manage to cook up a new one that i can remember

still dulan how this couldve happened


Added on August 10, 2012, 9:43 am
QUOTE(BotakPrince @ Aug 10 2012, 09:42 AM)
just changed my password for paypal.

gonna change my d3 password next.

in that order of importance. hahahhha
*
just dont recycle ur passwords bro, got any other accs using the same pass, tukar also

This post has been edited by The Amateur Working Bee: Aug 10 2012, 09:43 AM
BotakPrince
post Aug 10 2012, 09:52 AM

Casual
***
Junior Member
388 posts

Joined: Oct 2005


recycle? meaning using back the old password that i once used for the account? doesnt matter if i change the password for different accounts using the same password but just swap rght?
ie: password123 for paypal to passwordabc

passwordabc for diablo to password 123

swapping diablo and paypal passwords?!
Gen
post Aug 10 2012, 09:54 AM

Casual
***
Junior Member
410 posts

Joined: May 2005
From: PJ/KL


Hi folks, in the Bnet account management, where to click and change the security question ?
memphiz_zero88
post Aug 10 2012, 09:55 AM

My stars has gone. T_T
Group Icon
Staff
2,255 posts

Joined: Jul 2008
From: meditating at Mt Emei
QUOTE(The Amateur Working Bee @ Aug 10 2012, 09:42 AM)
exactly what im feeling now lol, lucky i manage to cook up a new one that i can remember

still dulan how this couldve happened


Added on August 10, 2012, 9:43 am
just dont recycle ur passwords bro, got any other accs using the same pass, tukar also
*
i only changed 2 characters in my 16-characters password. hope is enough unsure.gif

QUOTE(BotakPrince @ Aug 10 2012, 09:52 AM)
recycle? meaning using back the old password that i once used for the account? doesnt matter if i change the password for different accounts using the same password but just swap rght?
ie: password123 for paypal to passwordabc
 
passwordabc for diablo to password 123

swapping diablo and paypal passwords?!
*
recycle means using same password for other accounts.

means if u use 'abc123' for d3 password, u also use that password for paypal etc.
deathTh3Cannon
post Aug 10 2012, 09:58 AM

Getting Started
**
Junior Member
248 posts

Joined: Aug 2011
Username : uguysstillplayingdiablo3
Password : ialreadyuninstallandvendorallmyequips
TSThe Amateur Working Bee
post Aug 10 2012, 09:58 AM

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
QUOTE(Gen @ Aug 10 2012, 09:54 AM)
Hi folks, in the Bnet account management, where to click and change the security question ?
*
you need to send a support ticket to bnet admins to reset it for you, but they say they gonna prompt a security question change "soon", no specific time given

for your reference: http://www.ehow.com/how_8508652_reset-bliz...t-question.html


Added on August 10, 2012, 9:59 am
QUOTE(deathTh3Cannon @ Aug 10 2012, 09:58 AM)
Username : uguysstillplayingdiablo3
Password : ialreadyuninstallandvendorallmyequips
*
email:stillhavemydemonhuntertagonmysiggy

This post has been edited by The Amateur Working Bee: Aug 10 2012, 09:59 AM
metalfreak
post Aug 10 2012, 10:11 AM

Working out is not my routine, it's my new lifestyle
*******
Senior Member
3,300 posts

Joined: Jan 2003
Just changed my password and all =.=" meh...may be blizzard was being hacked or some shit...thats why the lag LOL


Balaclava
post Aug 10 2012, 10:30 AM

5-Star Swagger
*****
Senior Member
941 posts

Joined: Jul 2010
Actually, the letter contents were toned down from the following,

Dear users,

We had a breach in our systems and it wasn't prevented as soon as we could as our staffs were busy setting up the new rates for RMAH and explaining to the Board of Directors how money kept flowing in automatically. Sad but true, your accounts are compromised and while we kept ourselves busy counting figures that kept flowing in, it's up to you to safeguard your account.

kkthanksbye,
Mike
Kissan
post Aug 10 2012, 10:30 AM

Getting Started
**
Junior Member
137 posts

Joined: Apr 2012
From: Forensic Department
D3 so fvcked up... Already knew something shit is coming when those 2 cases of hacking happened to lyn members.

jay wilson meme : hacking then we DOUBLE IT.
neoengsheng
post Aug 10 2012, 11:05 AM

Getting Started
**
Junior Member
261 posts

Joined: Jul 2009
Quoting Bashiok
QUOTE
We've been taking the situation extremely seriously from the start, and have done everything possible to verify how and in what circumstances these compromises are occurring. Despite the claims and theories being made, we have yet to find any situations in which a person's account was not compromised through traditional means of someone else logging into their account through the use of their password. While the authenticator isn't a 100% guarantee of account security, we have yet to investigate a compromise report in which an authenticator was attached beforehand.

If your account has been hacked, please view the previous post for information on contacting our support department.
and Lylirra

QUOTE
We'd like to take a moment to address the recent reports that suggested that Battle.net® and Diablo® III may have been compromised. Historically, the release of a new game -- such as a World of Warcraft® expansion -- will result in an increase in reports of individual account compromises, and that's exactly what we're seeing now with Diablo III. We know how frustrating it can be to become the victim of account theft, and as always, we're dedicated to doing everything we can to help our players keep their Battle.net accounts safe -- and we appreciate everyone who's doing their part to help protect their accounts as well. You can read about ways to help keep your account secure, along with some of the internal and external measures we have in place to help us achieve our security goals, at our account security website here: http://www.battle.net/security" class="bml-link-url2">www.battle.net/security</a>.

We also wanted to reassure you that the Battle.net Authenticator and Battle.net Mobile Authenticator (a free app for iPhone and Android devices) continue to be some of the most effective measures we offer to help players protect themselves against account compromises, and we encourage everyone to take advantage of them. In addition, we also recently introduced a new service called Battle.net SMS Protect, which allows you to use your text-enabled cell phone to unlock a locked Battle.net account, recover your account name, approve a password reset, or remove a lost Authenticator. Optionally, you can set up the Battle.net SMS Protect system to send you a text message whenever unusual activity is detected on your account, keeping you aware of important (and possibly unwanted) changes.

For more information on the Authenticator, visit http://us.battle.net/support/en/article/ba...thenticator-faq

For more on the Battle.net Mobile Authenticator, visit http://us.battle.net/support/en/article/ba...thenticator-faq

For more on Battle.net SMS Protect, visit http://us.battle.net/support/en/article/ba...net-sms-protect

We also have other measures built into Battle.net to help protect players. Occasionally, when Battle.net detects unusual login activity that differs from your normal behavior -- such as logging in from an unfamiliar location -- we may prompt you for additional information (such as the answer to one of your security questions) and/or require you to perform a password reset through the Battle.net website. World of Warcraft players might be familiar with this security method already, and Diablo III players may begin to encounter it as well.

As always, if you think you've been the victim of an account compromise, head to the "Help! I've Been Hacked!" tool at <a href="http://us.battle.net/en/security/help for assistance.
Summary of the data that was illegally accessed:

With regard to Mobile Authenticators, information was taken that could potentially compromise the integrity of North American Mobile Authenticators."
"Email addresses
Answers to secret security questions
Cryptographically scrambled versions of passwords (not actual passwords)
Information associated with the Mobile Authenticator
Information associated with the Dial-in Authenticator

Inb4 Blizz no use authenticator.
cowithgun
post Aug 10 2012, 11:57 AM

A cow that can play notebook & phone
*******
Senior Member
2,248 posts

Joined: Sep 2010
Changed password. This is kind of serious. To be able to accessed all these info, the attackers are probably in the system for weeks...

Will wait for further instructions on how to change security question and update Mobile Authenticator.
gaeria84
post Aug 10 2012, 11:58 AM

Enthusiast
*****
Senior Member
837 posts

Joined: Mar 2005
Blizzard, I am disappoint sad.gif

Anyways, if you use the same password for your facebook, forums, banking, you might want to change that also.
squall0833
post Aug 10 2012, 12:11 PM

Regular
******
Senior Member
1,473 posts

Joined: Oct 2006
From: Jupiter


hmm,

if u got link paypal acc to bnet acc, they can get access to ur paypal meh?
they still need a password for ur paypal before doing any changes or transaction in ur b.net acc, the only thing they know about ur paypal is ur paypal email address

if u got cc added in bnet acc, then you really GG la

This post has been edited by squall0833: Aug 10 2012, 12:11 PM
gaeria84
post Aug 10 2012, 12:22 PM

Enthusiast
*****
Senior Member
837 posts

Joined: Mar 2005
Just had a thought.

user posted image
TSThe Amateur Working Bee
post Aug 10 2012, 12:23 PM

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
AHAHAHHAHAHA oh god lol
cowithgun
post Aug 10 2012, 12:26 PM

A cow that can play notebook & phone
*******
Senior Member
2,248 posts

Joined: Sep 2010
QUOTE(gaeria84 @ Aug 10 2012, 12:22 PM)
Just had a thought.
*
+1

LOL that is Mikey Morhamad

This post has been edited by cowithgun: Aug 10 2012, 12:27 PM
OnGx2
post Aug 10 2012, 12:33 PM

Getting Started
**
Junior Member
213 posts

Joined: May 2009
worst case, deebee joined diablo and raged and hacked all the CM and admin account to troll the players
SUSedge85
post Aug 10 2012, 01:18 PM

hepi hepi goyang bersama
******
Senior Member
1,299 posts

Joined: Jun 2008


more worried of my other acccounts. banking email etc... sigh...
polarzbearz
post Aug 10 2012, 02:32 PM

Gracie
*******
Senior Member
4,816 posts

Joined: Apr 2007


Thanks for sharing, changed mine after reading this rclxub.gif
olman
post Aug 10 2012, 03:56 PM

Regular
******
Senior Member
1,998 posts

Joined: Jan 2003


LOL so much for insisting always online is the best !!!

i told yall so, i told ya

This post has been edited by olman: Aug 10 2012, 04:08 PM
metalfreak
post Aug 10 2012, 04:13 PM

Working out is not my routine, it's my new lifestyle
*******
Senior Member
3,300 posts

Joined: Jan 2003
yeap. having to play online. f***ed up. =.="
Quazacolt
post Aug 10 2012, 05:32 PM

Riding couple
*******
Senior Member
5,366 posts

Joined: Jan 2007
From: KL Malaysia


QUOTE(olman @ Aug 10 2012, 03:56 PM)
i told yall so, i told ya
*
heh.
farkinid
post Aug 10 2012, 05:33 PM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


So I've had some time to sit down and think about this. This hacking is very bad. At this point, the attackers have got your
  • email address
  • secret question and answer
  • salted passwords[
I would like to state that even though the passwords are salted, its still crackable. Any basic maths geek will be able to tell you that with a large enough database, the constants can be deduced easily. This leaves your real password.

I have read an article about this and I think the author is on the right track when he says SRP may not be strong enough. Link to article. Read if you are interested in the theory of it.

But note that the author is an interested party when bashing Blizz AND like he said, its impossible to avoid break-ins. Although as long as there was a battlenet server to store and maintain user's characters, this would have happened. It doesn't matter if there was an offline aspect to D3.
TSThe Amateur Working Bee
post Aug 10 2012, 05:40 PM

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
QUOTE(farkinid @ Aug 10 2012, 05:33 PM)
So I've had some time to sit down and think about this. This hacking is very bad. At this point, the attackers have got your

  • email address
  • secret question and answer
  • salted passwords[
I would like to state that even though the passwords are salted, its still crackable. Any basic maths geek will be able to tell you that with a large enough database, the constants can be deduced easily. This leaves your real password.

I have read an article about this and I think the author is on the right track when he says SRP may not be strong enough. Link to article. Read if you are interested in the theory of it.

But note that the author is an interested party when bashing Blizz AND like he said, its impossible to avoid break-ins. Although as long as there was a battlenet server to store and maintain user's characters, this would have happened. It doesn't matter if there was an offline aspect to D3.
*
that 3 keys are actually all they need to access our acc, they can butter up whatever facts they want, secret answer alone can bypass half of the "security" they have for accs lol, and like u said, encrypted passwords are nothing these days
rickrick
post Aug 10 2012, 06:15 PM

Perth please be good to my business !!
****
Senior Member
505 posts

Joined: Apr 2007
From: Klang - Perth


I got a korean email from blizzard telling me to change password ( Legit from blizzard ).
This is it, Diablo 3 is finally dead to me.
Quazacolt
post Aug 10 2012, 08:40 PM

Riding couple
*******
Senior Member
5,366 posts

Joined: Jan 2007
From: KL Malaysia


QUOTE(rickrick @ Aug 10 2012, 06:15 PM)
I got a korean email from blizzard telling me to change password ( Legit from blizzard ).
This is it, Diablo 3 is finally dead to me.
*
goodbye
TSThe Amateur Working Bee
post Aug 10 2012, 09:53 PM

Regular
******
Senior Member
1,646 posts

Joined: Aug 2010
QUOTE(Quazacolt @ Aug 10 2012, 08:40 PM)
goodbye
*
ohyou.jpg
paranoid
post Aug 13 2012, 11:09 AM

I can go from 0 to bitch in 0.6seconds
******
Senior Member
1,235 posts

Joined: Nov 2004


there's a replica of d3 battle net page if some of you are careless most of the time.

those websites wont help u change your password, they are just retrieving ur passwords.
Teddysaur
post Aug 13 2012, 11:24 AM

Socially cawkward 🦄
***
Junior Member
435 posts

Joined: Oct 2010
http://us.battle.net/d3/en/forum/topic/6308360812?page=1

Har har harr in your face blizzard fan boys.
You flame those people who said they got hacked when the game released.
Now youre blaming "Ohh every system can be hack".

Quazacolt
post Aug 13 2012, 12:26 PM

Riding couple
*******
Senior Member
5,366 posts

Joined: Jan 2007
From: KL Malaysia


QUOTE(Teddysaur @ Aug 13 2012, 11:24 AM)
http://us.battle.net/d3/en/forum/topic/6308360812?page=1

Har har harr in your face blizzard fan boys.
You flame those people who said they got hacked when the game released.
Now youre blaming "Ohh every system can be hack".
*
you might want to look up what is the definition of blame.

either way kulle story bro
Teddysaur
post Aug 13 2012, 12:39 PM

Socially cawkward 🦄
***
Junior Member
435 posts

Joined: Oct 2010
QUOTE(Quazacolt @ Aug 13 2012, 12:26 PM)
you might want to look up what is the definition of blame.

either way kulle story bro
*
kk
Kissan
post Aug 15 2012, 12:56 PM

Getting Started
**
Junior Member
137 posts

Joined: Apr 2012
From: Forensic Department
This URGENT NEWS soon gonna be forgotten due to

Blizz "clouding" players with "1.0.4 blog update"

doh.gif

 

Change to:
| Lo-Fi Version
0.0267sec    0.93    5 queries    GZIP Disabled
Time is now: 2nd December 2025 - 03:58 PM